cvedb.io
CVE-2021-32101
HIGH · CVSS 8.2
EPSS exploitation probability: 0%
Published 2021-05-07T04:15:07.387 · Last modified 2026-06-17T03:52:47.243

Summary

The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerability, an unauthenticated attacker can register an account, bypassing the permission check of this portal's API. Then, the attacker can then manipulate and read data of every registered patient.

Affected products

open-emr — openemr

Does this affect you?

Add your gear to cvedb and we'll alert you only when open-emr ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.